<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to find users from Splunk UI  ???? in Security</title>
    <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391287#M9548</link>
    <description>&lt;P&gt;By  including edit_roles_grantable as a capability you have specified that any user assigned to that role will be limited to the capabilities that were included in that role. The result is that all the users who already existed and have been assigned to a role that has MORE capabilities than the role 'Pulsenewuser' will no longer be accessible. &lt;/P&gt;

&lt;P&gt;General behavior and configuration guidance for edit_roles_grantable:&lt;/P&gt;

&lt;P&gt;In the UI create a role called subadmin [or name of your choice] and make sure the following options are configured:&lt;/P&gt;

&lt;P&gt;[role_subadmin] &lt;BR /&gt;
edit_roles_grantable = enabled&lt;BR /&gt;
edit_roles = disabled&lt;BR /&gt;
edit_users = enabled&lt;/P&gt;

&lt;P&gt;When the new role  is created, the following change will be made in Splunk/etc/system/local/authorize.conf:&lt;/P&gt;

&lt;P&gt;grantableRoles = subadmin [you should confirm this - if the entry doesn't match that, make the change. ** After any manual edits of authorize.conf, use Settings &amp;gt; Access control &amp;gt; Authentication method  &amp;gt; Reload authentication configuration or changes won’t be applied.]&lt;/P&gt;

&lt;P&gt;Configure the subadmin role in the UI to include/exclude the capabilities to meet the specific limitations you want to impose on the subadmin. Create a newadmin user and assign them to the subadmin role. The user newadmin will only be able to see and use the capabilities that are included in the subadmin role. &lt;/P&gt;

&lt;P&gt;For example, if you want to remove access to the delete_by_keyword capability, configure the subadmin role as described above but without the delete_by_keyword capability. When the newadmin user logs into Splunk, they will not have that option in their list of capabilities. &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:40:50 GMT</pubDate>
    <dc:creator>tchimento_splun</dc:creator>
    <dc:date>2020-09-29T22:40:50Z</dc:date>
    <item>
      <title>Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391281#M9542</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We have Created Role  with name  "Pulsenewuser" with the capabilities (edit_user,edit_roles,edit_roles_grantable) .&lt;BR /&gt;
When we are adding  "Pulsenewuser" Role to the users  ,we are not able find the users from Splunk UI.&lt;/P&gt;

&lt;P&gt;please can you help me out from this ,we are using splunk 7.1.4 enterprise edition(same thing working fine in splunk 6.6.2)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391281#M9542</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2020-09-29T22:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391282#M9543</link>
      <description>&lt;P&gt;may i know, when you run &lt;CODE&gt;| rest /services/authorization/roles&lt;/CODE&gt; , do you get the "Pulsenewuser" listed out?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 12:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391282#M9543</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2019-01-03T12:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391283#M9544</link>
      <description>&lt;P&gt;@inventsekar &lt;/P&gt;

&lt;P&gt;Thanks for your reply..&lt;/P&gt;

&lt;P&gt;Yes ,am getting the "Pulsenewuser" list&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 13:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391283#M9544</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2019-01-03T13:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391284#M9545</link>
      <description>&lt;P&gt;@inventsekar &lt;BR /&gt;
yes,we did logout and login.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 07:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391284#M9545</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2019-01-04T07:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391285#M9546</link>
      <description>&lt;P&gt;What is your problem exactly? The role is used to create new users but you can not create new users? Are the users found in the following rest call?&lt;BR /&gt;
    | rest /services/authentication/users&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 09:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391285#M9546</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-01-04T09:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391286#M9547</link>
      <description>&lt;P&gt;when you create Pulsenewuser, did you just create from zero or did you create by cloning an already existing role and edited?&lt;BR /&gt;
if you created Pulsenewuser from zero, maybe, delete it and clone a very basic role and edit/update the roles. &lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 11:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391286#M9547</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2019-01-04T11:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to find users from Splunk UI  ????</title>
      <link>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391287#M9548</link>
      <description>&lt;P&gt;By  including edit_roles_grantable as a capability you have specified that any user assigned to that role will be limited to the capabilities that were included in that role. The result is that all the users who already existed and have been assigned to a role that has MORE capabilities than the role 'Pulsenewuser' will no longer be accessible. &lt;/P&gt;

&lt;P&gt;General behavior and configuration guidance for edit_roles_grantable:&lt;/P&gt;

&lt;P&gt;In the UI create a role called subadmin [or name of your choice] and make sure the following options are configured:&lt;/P&gt;

&lt;P&gt;[role_subadmin] &lt;BR /&gt;
edit_roles_grantable = enabled&lt;BR /&gt;
edit_roles = disabled&lt;BR /&gt;
edit_users = enabled&lt;/P&gt;

&lt;P&gt;When the new role  is created, the following change will be made in Splunk/etc/system/local/authorize.conf:&lt;/P&gt;

&lt;P&gt;grantableRoles = subadmin [you should confirm this - if the entry doesn't match that, make the change. ** After any manual edits of authorize.conf, use Settings &amp;gt; Access control &amp;gt; Authentication method  &amp;gt; Reload authentication configuration or changes won’t be applied.]&lt;/P&gt;

&lt;P&gt;Configure the subadmin role in the UI to include/exclude the capabilities to meet the specific limitations you want to impose on the subadmin. Create a newadmin user and assign them to the subadmin role. The user newadmin will only be able to see and use the capabilities that are included in the subadmin role. &lt;/P&gt;

&lt;P&gt;For example, if you want to remove access to the delete_by_keyword capability, configure the subadmin role as described above but without the delete_by_keyword capability. When the newadmin user logs into Splunk, they will not have that option in their list of capabilities. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:40:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Not-able-to-find-users-from-Splunk-UI/m-p/391287#M9548</guid>
      <dc:creator>tchimento_splun</dc:creator>
      <dc:date>2020-09-29T22:40:50Z</dc:date>
    </item>
  </channel>
</rss>

